<div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Mon, Mar 12, 2018 at 5:55 PM Andrew Morgan <<a href="mailto:morgan@orst.edu">morgan@orst.edu</a>> wrote:</div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
At first, I thought this was a new restriction in v3 of the protocol too.<br>
However, take a look at section 3.7 of the v2 spec... Same character<br>
class restriction.<br></blockquote><div><br></div><div>Wow. I was so sure that the character set was an editorialization on top of the original document [1], but I'm just wrong. That raises the priority in my view to "something we probably should fix." Thinking on it more, it's probably not too much work to simply use base 32 encoding and swap out the "=" padding character with "-" in a post-encoding/pre-decoding step. I've filed an issue to track it:</div><div><br></div><div><a href="https://issues.shibboleth.net/jira/browse/IDP-1265">https://issues.shibboleth.net/jira/browse/IDP-1265</a><br></div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Given the character class restriction, I wonder if the patch will ever be<br>
accepted into mod_auth_cas. :/<br></blockquote><div><br></div><div>While your observation about character set requirements in the protocol makes it less palatable perhaps, one could argue it's a reasonable improvement nonetheless. In any case I'm fairly certain dhawes would consider positive feedback on the patch as a sign that it should be accepted.</div><div><br></div><div>M<a href="mailto:users-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div><div>[1] <a href="https://web.archive.org/web/20110430030314/http://www.jasig.org/cas/protocol">https://web.archive.org/web/20110430030314/http://www.jasig.org/cas/protocol</a></div></div></div>